Live data from Hacker News

Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

washingtonpost.com

161–170 of 456 posts

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#163
post #84

Earlier quoted context omitted.

It’s impossible to stop using M365 while stopping usage of SharePoint (cloud or on-premises). See https://news.ycombinator.com/item?id=44640219 Here’s just one example: Each M365 Teams Team creates an M365 Group which creates a SharePoint site and Exchange mailbox. Teams channel files are stored in that SharePoint site. Teams channel messages are stored in the Exchange mailbox. Private files dropped in Teams are stor…

> Private Teams messages are stored in individual Exchange mailboxes. Good lord. It truly is a layer of dung layered upon more layers of dung.

Throwaway account so keep this comment separate from my main account.

I used to work within the Office group. The way that data is organized in Exchange is mind-boggling -- and not in a good way, IMO. Its design is from decades ago, and trying to understand how to find something really takes a lot of experience. Without going into any gruesome details of how it works, I'll just say that it is a HUGE hurdle to being productive for day-to-day work.

Similarly, I'm not surprised that there's some kooky way that the Teams folks shoehorned their data into the existing Exchange system -- they probably have no other way to operate at that scale without taking years in writing their own database system. (I can't imagine that using SQL Server to do this would be viable, either, given what they want to do and the capabilities already built on top of Exchange.)

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#164

> CISA advises vulnerable organizations [...] to disconnect affected products from the public-facing Internet until an official patch is available. It's interesting to me that you'd go the hassle of hosting your own SharePoint on prem, but leave it internet facing. I would have assumed a the Venn diagram of these organizations to be entirely contained in orgs forcing you to use a VPN.

The product was explicitly promoted as being useful to run public websites. Before cloud took off we had Microsoft sales people in our office announcing the death of Wordpress with the latest Sharepoint release. That position may be old, but plenty of orgs live in the past.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#165
post #43

Earlier quoted context omitted.

Genuinely asking - is there a Linux alternative to Sharepoint? I couldn't care less if it was lit on metaphorical fire and dumped into the sea, but a lot of orgs using it extensively.

Nextcloud, particularly with the Collabora Office integration for real-time collaborative document editing. It's got some rough edges but I'd say it suits the majority of use cases now. I suggest spinning up a copy of the community edition in a VM to give it a spin, I was pleasantly surprised. There is a lot of money getting poured in right now as entities outside the US are exploring ways to ditch American software.

Works easily enough on digital ocean too.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#166

Wasn’t Microsoft just recently using Chinese people living in China to administer DOD servers? I would guess they use Sharepoint inside the DOD?

Link: https://www.reuters.com/world/us/microsoft-stop-using-engine...

That is... crazy.

Would the CCP allow their cloud infra to be administrated by US staff in the US? Never.

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#167

> CISA advises vulnerable organizations [...] to disconnect affected products from the public-facing Internet until an official patch is available. It's interesting to me that you'd go the hassle of hosting your own SharePoint on prem, but leave it internet facing. I would have assumed a the Venn diagram of these organizations to be entirely contained in orgs forcing you to use a VPN.

I would assume some orgs made it public facing for covid and it remained like that

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#168
post #159

If I am ever on the board of a company, I will always vote no confidence in the dipshit CTO or founder that willingly install/mandate use of Microsoft junk in the company. As a corporate drone that has accidentally opened various Microsoft office suite links inside of Teams. My dislike for anything Microsoft continues to grow. Am I surprised that sharepoint has vulnerabilities? Hell no.

What would you replace it with? Once an org gets to a certain size, they need something like sharepoint, and would they be any more secure?

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#169
post #159

If I am ever on the board of a company, I will always vote no confidence in the dipshit CTO or founder that willingly install/mandate use of Microsoft junk in the company. As a corporate drone that has accidentally opened various Microsoft office suite links inside of Teams. My dislike for anything Microsoft continues to grow. Am I surprised that sharepoint has vulnerabilities? Hell no.

Once worked at a place in 2017 with a dipshit CIO. Guy spent his entire time trying to evangelize Teams as the reason to switch to Microsoft. He ended up leaving 11 months into the gig and we were more than happy to stay on Slack.

It feels like Microsoft has a (bad) deal with every 3rd rate IT leader where the IT leader eschews Microsoft's BS in exchange for being "unfireable" because "who else knows how all the Microsoft stuff works?"

Re: Global hack on Microsoft Sharepoint hits U.S., state agencies, researchers say

#170
post #152

We need more Red Hat and less Microsoft in the on-prem enterprise business. These exploitable vulnerabilities are unacceptable when your customers are the likes of DoD. No one considers Google anything less than an impenetrable fortress, but when it's some government entity responsible for keeping American lives safe it's like "ah yeah they probably have a vulnerable on-prem Sharepoint that could easily be pwned." So…

Not sure how it is in US but where I am, it is mostly because of corruption.
Post reply on HN